acr — Authentication Context Class Reference

Location: payload · Format: string

Indicates the authentication method/assurance level actually used (e.g. password-only vs. multi-factor), as a string agreed between OP and RP out of band. Only meaningful to enforce when the RP requested a specific level via acr_values in the auth request.

Defined in OpenID Connect Core 1.0 §2.

Decode a JWT and inspect its acr claim in the TokenPrism debugger — free, entirely in your browser.